Critical Citrix NetScaler Vulnerability CVE-2026-19490 Actively Exploited
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity authentication bypass vulnerability in Citrix NetScaler, tracked as CVE-2026-19490, to its Known Exploited Vulnerabilities (KEV) catalog following active exploitation in the wild. Boasting a CVSS score of 9.3, this security defect impacts all NetScaler ADC and NetScaler Gateway appliances configured as a gateway (including SSL VPN, ICA Proxy, CVPN, and RDP Proxy) or as an AAA virtual server. Although Citrix released patches for the flaw on August 19, 2026, threat actors began actively exploiting the vulnerability around September 3, 2026, shortly after a public proof-of-concept exploit was published on GitHub. Federal agencies and enterprise organizations must prioritize patching affected systems immediately to mitigate the risk of unauthorized remote access.
Severity: Critical
Threat Details and IOCs
| CVEs: | CVE-2026-19489, CVE-2026-19490, CVE-2026-3055, CVE-2026-4368 |
|---|---|
| Technologies: | Citrix NetScaler ADC, Citrix NetScaler Application Delivery Controller, Citrix NetScaler Gateway, NetScaler ADC, NetScaler Gateway |
| Attacker Countries: | Australia, China, Germany, Japan, United States |
| Victim Industries: | Automotive, Communication Services, E-commerce, Education, Financial Services, Government, Healthcare, Insurance, Life Sciences, Manufacturing, Professional Services, Retail, Technology Hardware, Telecommunications, Transportation |
| Victim Countries: | Australia, Belgium, Canada, United States |
Mitigation Advice
- Patch all NetScaler ADC and NetScaler Gateway appliances vulnerable to CVE-2026-19490 immediately.
- Initiate a vulnerability scan across the entire network to identify all instances of NetScaler ADC and Gateway appliances vulnerable to CVE-2026-19490.
- Review NetScaler logs for requests to authenticated endpoints that lack a corresponding successful login event and investigate any unexpected session creations.
- Monitor firewall and network flow logs for anomalous outbound connections originating from your NetScaler appliances and investigate any suspicious traffic.
Compliance Best Practices
- Implement or improve an asset management program to maintain a continuous and accurate inventory of all internet-facing hardware and software, including their configurations and patch levels.
- Review and enhance network segmentation to ensure perimeter devices like NetScaler appliances are isolated from critical internal servers and user subnets, limiting their access to only what is strictly necessary.
- Establish a formal, risk-based vulnerability management policy that incorporates threat intelligence, such as the CISA KEV catalog, to define strict patching timelines for critical, internet-facing systems.
- Ensure all perimeter network devices, including NetScaler appliances, are configured to send detailed logs to a central SIEM and develop detection rules based on potential misuse and anomalous activity.
https://cyberpress.org/critical-citrix-netscaler-authentication-bypass-flaw/
https://gbhackers.com/critical-citrix-netscaler-flaw/
https://meterpreter.org/citrix-netscaler-flaw-cve-2026-19490/
https://securityonline.info/netscaler-authentication-bypass-cve-2026-19490/
https://socprime.com/blog/cve-2026-19490-analysis/
https://socradar.io/blog/cve-2026-19490-netscaler-auth-bypass/
https://sploitus.com/exploit?id=C335E9AF-68CB-5EFD-9DC7-C02CA5B4B451
https://thecyberexpress.com/citrix-netscaler-vulnerabilities-prompt-patch/
https://thehackernews.com/2026/08/critical-netscaler-flaw-can-bypass.html
https://www.helpnetsecurity.com/2026/08/21/citrix-netscaler-gateway-cve-2026-19490/
https://www.securityweek.com/critical-netscaler-vulnerability-exploited-in-attacks/
Cisco FMC Vulnerabilities CVE-2026-20079 and CVE-2026-20316 Exploited by Sandworm and Qilin Ransomware
State-sponsored and financially motivated threat actors are actively exploiting two critical vulnerabilities in the web interface of Cisco's Secure Firewall Management Center (FMC): CVE-2026-20079 and CVE-2026-20316. CVE-2026-20079 is an authentication bypass flaw stemming from an improper boot-time system process that allows remote, unauthenticated attackers to achieve root access by sending crafted HTTP requests. CVE-2026-20316 involves hard-coded static credentials for a low-privileged account, enabling unauthenticated remote login. Cisco Talos has identified three distinct intrusion clusters leveraging these vulnerabilities: the first deploys a malicious web shell and JAR file in the CSM Tomcat webroot to harvest credentials; the second, attributed to the Russian state-sponsored group Sandworm, modifies the `license.tmp` file to establish a reverse shell and install a network-sniffing implant; and the third, linked to Qilin ransomware operators, uses the static credentials to conduct reconnaissance, disable antivirus software, and deploy ransomware. Organizations are strongly urged to apply the available Cisco hotfixes immediately or restrict internet access to the FMC management interface to mitigate these active threats.
Severity: Critical
Threat Details and IOCs
| Malware: | Agenda, AgendaCrypt, Cyclops Blink, CyclopsBlink, Qilin |
|---|---|
| CVEs: | CVE-2026-20079, CVE-2026-20131, CVE-2026-20316 |
| Technologies: | Adobe Commerce, Cisco Secure Firewall Management Center, Cisco Security Cloud Control, Linux, Microsoft Windows, N-able N-central |
| Threat Actors: | Agenda, APT44, Interlock, Qilin, Sandworm, UAT-11823, UAT-11988, UAT-12197 |
| Attacker Countries: | Russia |
| Attacker IPs: | 104[.]218[.]165[.]253, 208[.]123[.]119[.]215, 43[.]204[.]2[.]142, 89[.]34[.]96[.]56, 91[.]214[.]78[.]118 |
| Attacker URLs: | /login.cgi?logon=Continue, /pjb.cgi, /sajaxintf.cgi?rs=callServerFunc, /ui/user/general |
| Attacker Hashes: | 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461, b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d, db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e |
| Victim Industries: | Automotive, Cloud Infrastructure, Construction, Education, Energy, Financial, Financial Services, Government, Healthcare, Hospitality, Industrial Sector, Legal Services, Manufacturing, Professional Services, Retail, Technology Hardware, Telecommunications, Transportation |
| Victim Countries: | Brazil, Canada, France, Germany, India, Israel, Italy, Japan, Malaysia, Mexico, Russia, South Korea, Spain, Sweden, Ukraine, United Kingdom, United States |
Mitigation Advice
- Immediately apply the Cisco hotfixes for CVE-2026-20079 and CVE-2026-20316 to all on-premise Cisco Secure Firewall Management Center (FMC) instances.
- If patching cannot be done immediately, restrict all access to the Cisco FMC management web interface from the public internet using firewall rules.
- Scan the file systems of all Cisco FMC devices, specifically the CSM Tomcat webroot directory, for any unknown or malicious web shells and JAR files.
- Inspect the 'license.tmp' file on all Cisco FMC devices for any recent or unauthorized modifications.
- Review network egress logs from your Cisco FMC devices for any suspicious or unexpected outbound connections to unknown IP addresses.
- Analyze authentication logs on Cisco FMC devices for successful logins from unusual IP addresses or at unusual times, which could indicate exploitation of the static credentials in CVE-2026-20316.
Compliance Best Practices
- Develop and enforce a formal patch management policy that defines timelines and procedures for applying security updates to critical, internet-facing network infrastructure.
- Audit and re-architect your network to ensure all device management interfaces, including the Cisco FMC, are segregated onto a dedicated, non-public management network with strict access controls.
- Implement a security hardening standard for all new devices and software that includes a mandatory step to change or disable all default and static credentials before deployment.
- Deploy and tune an Endpoint Detection and Response (EDR) agent on critical infrastructure servers, including the Cisco FMC, to detect and alert on post-exploitation behaviors like credential dumping and reconnaissance commands.
- Implement a File Integrity Monitoring (FIM) solution on critical systems like the Cisco FMC to alert on unauthorized changes to system and configuration files.
https://blog.talosintelligence.com/fmc-ongoing-exploitation/
https://buaq.net/go-441380.html
https://securityonline.info/cisco-fmc-vulnerabilities-exploited/
https://sploitus.com/exploit?id=40880921-C39C-58D4-B99F-0A7459D57358
https://www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316/
https://www.hendryadrian.com/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
https://www.securityweek.com/organizations-warned-of-cisco-secure-fmc-exploitation/
Check Point Quantum Security Gateways Affected by Critical CVE-2026-85102 Vulnerability
A critical certificate validation vulnerability, identified as CVE-2026-85102 with a CVSS v3.1 score of 9.8, affects Check Point Quantum Security Gateways, impacting both remote access and site-to-site VPN connections. Classified under CWE-295 (Improper Certificate Validation), this flaw allows an unauthenticated remote attacker to bypass trust validation controls by submitting forged certificate data during the VPN negotiation phase, leading to unauthorized remote code execution. The vulnerability impacts Check Point Security Gateway versions R82.10 (Jumbo Hotfix Take 43 and earlier), R82 (Jumbo Hotfix Take 125 and earlier), R81.20 (Jumbo Hotfix Take 165 and earlier), R81.10.X, R82.00.X, Spark Firewalls on R81.10.X and R82.00.X, as well as end-of-support branches from R80 through R81.10. While there is no evidence of active exploitation or public proof-of-concept, immediate remediation is advised. Organizations should apply the corresponding Jumbo Hotfix Accumulators (Take 44 for R82.10, Take 126 for R82, and Take 166 for R81.20), utilize the respective LivePatches, or upgrade Spark Firewalls to R82.00.10 Build 2325 or R81.10.17 Build 4968. For site-to-site VPNs where patching is delayed, a temporary workaround involves disabling implied VPN rules and manually restricting UDP/500 and UDP/4500 access to specific peer IP addresses, though this does not apply to locally managed Spark Firewalls. Legacy, unsupported versions must be migrated to supported branches as no patches will be provided.
Severity: Critical
Threat Details and IOCs
| CVEs: | CVE-2026-16232, CVE-2026-50751, CVE-2026-85102, CVE-2026-85103 |
|---|---|
| Technologies: | Check Point Quantum Security Gateway, Check Point Quantum Spark, Check Point Security Management |
| Victim Industries: | Education, Financial Services, Government, Healthcare, Industrial Control Systems, Manufacturing, Retail, Utilities & Energy |
| Victim Countries: | Canada, United States |
Mitigation Advice
- Identify all Check Point Quantum Security Gateway and Spark Firewall appliances in the environment and determine their current software version and Jumbo Hotfix level to confirm if they are vulnerable to CVE-2026-85102.
- Apply the vendor-supplied patches to all identified vulnerable Check Point Quantum Security Gateway and Spark Firewall appliances. Follow the specific Jumbo Hotfix, LivePatch, or build version guidance provided in the advisory for each product branch.
- For site-to-site VPNs, if patching is delayed, implement the recommended workaround by disabling implicit VPN rules and creating explicit firewall rules to only allow IKE and IPsec NAT-T traffic (UDP/500 and UDP/4500) from the specific IP addresses of trusted VPN peers.
Compliance Best Practices
- Develop and execute a plan to migrate all Check Point Security Gateways running end-of-support (EoS) versions (R80.x, R81, R81.10) to a vendor-supported software branch.
- Review and formalize the patch management policy to enforce strict timelines for applying critical security updates to all internet-facing network infrastructure, including firewalls and VPN concentrators.
- Implement or enhance a centralized asset management system to maintain a continuously updated inventory of all network devices, their software versions, and patch status.
- Review and improve network segmentation to isolate the management interfaces of perimeter security devices from general corporate and user networks, limiting the potential impact of a device compromise.
Critical Palo Alto Networks PAN-OS CVE-2026-0310 Vulnerability Allows Remote Code Execution
A critical out-of-bounds write vulnerability, tracked as CVE-2026-0310 with a CVSS v3.1 score of 9.1, has been identified in the XML document parsing function of Palo Alto Networks PAN-OS, affecting both the web management and data plane interfaces. An unauthenticated remote attacker can exploit this flaw by sending specially crafted XML data, leading to an out-of-bounds memory write. On PA-Series hardware appliances, this allows for remote code execution with root privileges, while on VM-Series virtual appliances and Panorama, it results in a denial of service; Prisma Access and Cloud NGFW are also affected but require authentication and restricted network access for exploitation. The vulnerability impacts multiple versions across PAN-OS branches 10.2, 11.1, 11.2, 12.1, and 12.2, as well as unsupported legacy versions. Although there is currently no evidence of active exploitation or public proof-of-concept code, immediate remediation is advised by upgrading to patched releases, such as PAN-OS 12.2.3, 12.1.4-h10, 11.2.4-h21, 11.1.4-h36, and 10.2.7-h37 or higher, depending on the specific maintenance branch in use.
Severity: Critical
Threat Details and IOCs
| CVEs: | CVE-2026-0310 |
|---|---|
| Technologies: | Palo Alto Networks Next-Generation Firewall, Palo Alto Networks Panorama, Palo Alto Networks PAN-OS, Palo Alto Networks PA-Series, Palo Alto Networks Prisma Access, Palo Alto Networks VM-Series |
| Victim Industries: | Automotive, Education, Energy, Financial Services, Government, Healthcare, Manufacturing, Oil & Gas, Public Sector, Retail, Technology Hardware, Telecommunications, Transportation, Utilities |
| Victim Countries: | France |
Mitigation Advice
- Immediately identify all Palo Alto Networks PA-Series, VM-Series, and Panorama appliances in the environment and document their current PAN-OS software version.
- Apply the security patches provided by Palo Alto Networks to upgrade all vulnerable PAN-OS appliances to a recommended fixed version.
- Implement strict access control lists or firewall rules to restrict network access to the PAN-OS management web interface, allowing connections only from a dedicated and trusted set of internal administrative IP addresses.
- For deployments using Cloud NGFW or Prisma Access, contact Palo Alto Networks support or monitor the service portal to confirm that the patch for CVE-2026-0310 has been successfully applied by the vendor.
Compliance Best Practices
- Implement an automated asset management system to maintain a real-time inventory of all network devices, including their hardware models, software versions, and support status, to accelerate future incident response activities.
- Design and implement a dedicated, out-of-band management network for all critical infrastructure, including firewalls, to ensure administrative interfaces are completely isolated from general user traffic and the public internet.
- Establish and enforce a formal hardware and software lifecycle management policy that mandates the replacement or upgrade of network equipment before it reaches its end-of-life (EOL) date.
- Develop a formal vulnerability management program that includes regular, authenticated scanning of network infrastructure, risk-based prioritization of findings, and defined Service Level Agreements (SLAs) for patching critical vulnerabilities.
New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access
Following the release of the September 2026 Patch Tuesday security updates, an anonymous security researcher known as Nightmare Eclipse disclosed a new Microsoft Defender zero-day exploit named "ShieldCrash." This vulnerability functions as a bypass for the recently patched ShieldBreak privilege escalation flaw (CVE-2026-69414), which itself bypassed the RoguePlanet vulnerability patched in July. The ShieldCrash proof-of-concept exploit allows attackers to perform arbitrary file reads with SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems, though it does not currently grant write access. This zero-day release is part of an ongoing dispute between the researcher and Microsoft over bug bounty and vulnerability disclosure practices, leaving several of the researcher's previously disclosed Windows and Defender flaws still lacking official patches.
Severity: Critical
Threat Details and IOCs
| Malware: | Chrysaor, Pegasus, Pegasus for Android, Pegasus for iOS, StreamRat, ted, Ted Backdoor |
|---|---|
| CVEs: | CVE-2020-17103, CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586, CVE-2026-50656, CVE-2026-69414 |
| Technologies: | Avast Antivirus, CrowdStrike, Kaspersky Endpoint Security, Microsoft Defender, Microsoft Windows, Microsoft Windows 11 Enterprise, Microsoft Windows Server |
| Threat Actors: | ChaoticEclipse, DeadEclipse, INFINITENIGHTMARE, MSNightmare, NightmareEclipse |
| Attacker Countries: | China, Iran, Russia |
| Attacker Domains: | github[.]com |
| Attacker URLs: | hxxps[://]github[.]com/MSNightmare/ShieldCrash |
| Victim Industries: | Education, Financial Services, Gaming, Government, Healthcare, Logistics, Manufacturing, Technology Hardware |
| Victim Countries: | United States |
Mitigation Advice
- Use your vulnerability management tool to verify that all Windows endpoints and servers have successfully installed the September 2026 security updates and that the Microsoft Defender Antimalware Engine is fully updated to mitigate previously patched vulnerabilities like ShieldBreak and RoguePlanet.
- In your SIEM and EDR platforms, create and enable detection rules to alert on anomalous file read operations by system-level processes, unexpected child processes spawned by Microsoft Defender services (MsMpEng.exe), and other behaviors indicative of local privilege escalation.
- Brief the security operations team on the 'ShieldCrash' zero-day, its capability to grant SYSTEM-level file read access, and the current lack of a patch. Emphasize heightened scrutiny of alerts related to privilege escalation on Windows assets.
Compliance Best Practices
- Initiate a project to implement and enforce the Principle of Least Privilege (PoLP) across the enterprise. Audit user and service accounts to ensure they only have the minimum permissions necessary for their roles, restricting an attacker's ability to run exploit code after an initial compromise.
- Plan and deploy an application control solution, such as Windows Defender Application Control (WDAC) or AppLocker, to restrict executable files, scripts, and DLLs from running unless they are explicitly allowed. Start with audit mode on critical servers to build a baseline of normal activity.
- Evaluate and procure a supplementary Endpoint Detection and Response (EDR) solution from a different vendor to layer on top of Microsoft Defender. This provides diverse and redundant visibility, detection, and response capabilities on endpoints.
- Enhance your vulnerability management program to include a formal process for tracking known, unpatched zero-day vulnerabilities. This process should define how to identify and apply compensating controls, communicate risk to stakeholders, and monitor for an official patch.
https://cyberpress.org/new-windows-defender-shieldcrash-0-day/
https://gbhackers.com/windows-defender-shieldcrash-0-day/
https://securityonline.info/windows-defender-0day-cve-2026-69414/
https://socradar.io/blog/shieldcrash-poc-microsoft-defender-fix-bypass/
https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html
https://www.cyberkendra.com/2026/09/shieldcrash-zero-day-bypasses.html
https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/


